You currently have javascript disabled. Several functions may not work. Please re-enable javascript to access full functionality.

Register a free account to unlock additional features at BleepingComputer.com

Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Hijackthis Log... Infected With "trojan Horse Dialer.btc"

It's been nearly a week and I can't seem to kill this dialer... When I use Internet explorer my AVG virus scanner pops up and keeps finding "Trojan Horse Dialer.BTC" in c:\WINDOWS\TEMP... It looks something like this "WIN????.tmp.exe", except the the numbers and letters after WIN keep changing. Also other WIN????.tmp files keep showing up in the same folder, even when I'm not doing anything at all on my puter. AVG also occasionally finds the same Dialer.BTC in c:WINDOWS\Temporary Internet Files\Content.IE5\FFHRFLWS, only it's called "SRV???[1].exe" and again the letters after SRV keep changing... I've downloaded and ran "AdAware", "Spybot Search and Destroy" and "TrojanHunter" (evaluation) as well as my AVG virus scanner. I've used each of these programs many times in last few days, both in regular and Safe Mode as well as countless internet searches to find help. Hijack This is my last resort...

BC AdBot (Login to Remove)

Update... After waiting a while for a reply I decided to investigate my "Hijack This" log file using links found at this page ( http://www.spywareinfo.com/~merijn/htlogtutorial.html ). I analized each of the 02,03 and 04 lines using the links provided and the only line of the log that I couldn't figure out a purpose for was "O4 - HKLM\..\Run: [WINTZS32] rundll32 WINTZS32.DLL,run"... So I told Hijack this to fix that line. It seems to have done the trick. My AVG virus scanner has stopped popping up with alerts when I use Internet Explorer. And the "WIN????.tmp" files have stopped reproducing in c:\WINDOWS\TEMP, so I think I fixed my problem. Any Mod can probably delete this thread, unless someone spots a problem that I missed... I'll check back once in a while. Thanks